What security resources should a white-hat *developer* follow these days? [closed]

What sites, twitter accounts, FOSS software should a white-hat code ‘hacker’ follow these days?

Do Include:

Late breaking information on new security issues (RSS, Twitter, etc)
A website that tracks unpatched security issues per vendor
Continue reading What security resources should a white-hat *developer* follow these days? [closed]